Auto Intune Enrollment - Only for selected user (IE none) but still being auto enrolled?

Jonathan Telling 20 Reputation points
2025-01-21T23:30:58.61+00:00

Hi All.

I've been doing some testing of a few things (see my old post) and I'm confused by the following:

I created a VM in Azure, Windows 11 Ent. This VM was not enabled for AADLogonForWindows (Login using Entra ID) as I'm wanting to do some testing against a test tenant (IE a different tenant from where the subscription is connected ).

I logged into the new VM and AAD joined it to the test tenant, all good and as expected.
The new VM now has an AAD joined device and is Intune enrolled.

My next testing is to do with enrolling in Intune in a different way, outside the Auto enrollment.
I changed the MDM auto enrollment settings from "all" to "some" and selected an empty group that I'll use later.

I then unenrolled the device from AAD/Intune (locally from the VM not from the portal). All good, no devices for the test VM to be found.

I then AAD joined the VM and it still auto enrols in Intune.. At first I thought this was a time issue (not giving Intune enough time to replicate the settings around) and so I tested it again around 2hrs later and it still auto enroled...

Am I doing something wrong, or is this just lag time in Intune?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,569 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 53,086 Reputation points Microsoft External Staff
    2025-01-22T01:18:10.38+00:00

    @Jonathan Telling, Thanks for posting in Q&A. From your description, I know we have changed the Automatic enrollment from All to some. But the device still auto enrolls into Intune.

    Here I have some suggestions:

    1, For the MDM auto enrollment, please confirm if we change it under MDM user scope of Microsoft Intune. Please change to none to see if the result will be different.

    https://learn.microsoft.com/en-us/mem/intune/enrollment/quickstart-setup-auto-enrollment#set-up-automatic-enrollment

    2, When unenroll the device from Intune and Microsoft Entra ID, please ensure the devices records in both Intune and Microsoft Entra ID portal are removed. In addition, please clean the enrollment registry information under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments.

    In addition, please check the device information on the device side Setting->Accounts->Access work or school, to see which account has info button which means enroll into Intune and confirm if it is enrolled into the previous tenant or IE tenant.

    Please try the above suggestion and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Jonathan Telling 20 Reputation points
    2025-02-03T15:56:48.1133333+00:00

    I've managed to stop auto enrolment into Intune when adding a joining a device to the AAD tenant.
    From the portal I searched for "mobility (MDM and WIP)".
    Which has the following:

    • Microsoft Intune
    • Microsoft Intune Enrollment

    Everything I've read says that the "Microsoft Intune" is the on that is used (also the settings match what is in Intune for Auto Enrolment) but I thought I'll change "Microsoft Intune Enrollment" to test. And that worked, I can no join a device to the tenant without auto enrollment into Intune. All this so I can test manually enrolling a device directly into Intune without duplicate devices being created in AAD. :)

    0 comments No comments

  3. Crystal-MSFT 53,086 Reputation points Microsoft External Staff
    2025-02-04T02:28:58.1933333+00:00

    @Jonathan Telling, Thanks for sharing your solution here. In general, The Microsoft Intune setting in the portal is used to configure automatic enrollment policies for devices joining the Microsoft Entra ID (formerly Azure AD) tenant. The Microsoft Intune Enrollment setting specifically controls the initial enrollment behavior of devices. By Default, we will not configure Microsoft Intune Enrollment. Just configure under Microsoft Intune. From your description, it seems the Microsoft Intune Enrollment is configured before and now when we change it, the automatic enrollment stops.

    Here, please let me write a summary for our issue

    Issue:

    Auto Intune Enrollment - Only for selected user (IE none) but still being auto enrolled

    Resolution:

    User's image

    Thanks for your time and have a nice day!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.